Black & White Path
Author

Black & White Path

We are the beacon of the cyber world, a stepping stone on the road to security.

611
Articles
0
Likes
3.4k
Views
0
Comments
Recent Articles

Latest from Black & White Path

100 recent articles max
Black & White Path
Black & White Path
Aug 11, 2026 · Information Security

Is Your AI Assistant a Digital Employee or a Hacker?

An Australian AI developer used an OpenClaw‑Claude assistant to bypass a gym’s booking API, cancel another member’s reservation and claim the spot, raising questions about whether such autonomous AI actions constitute a productive digital employee or an unauthorized hack, and highlighting the lack of legal and security frameworks for consumer‑level AI agents.

AIAPI VulnerabilityLegal Issues
0 likes · 4 min read
Is Your AI Assistant a Digital Employee or a Hacker?
Black & White Path
Black & White Path
Aug 10, 2026 · Information Security

Black Hat Exposes Pass‑the‑Passkey Attack: Windows Event Log Extraction and Replay of YubiKey Tokens

Researchers at Black Hat 2026 demonstrated a Pass‑the‑Passkey attack where, after gaining local code execution, an adversary reads Windows event logs to harvest WebAuthn authentication statements from a YubiKey, then replays them to Microsoft Entra ID, bypassing MFA without physical key possession.

Authentication ReplayMicrosoft Entra IDPass-the-Passkey
0 likes · 4 min read
Black Hat Exposes Pass‑the‑Passkey Attack: Windows Event Log Extraction and Replay of YubiKey Tokens
Black & White Path
Black & White Path
Aug 10, 2026 · Information Security

CVE-2026-45454: SharePoint Server Upload.aspx Path Traversal Leads to Remote Code Execution

The AretiQ security team disclosed a path‑traversal flaw in SharePoint Server's Upload.aspx page that lets an authenticated user with Contribute rights upload files to any library, and when PageParserPaths permits server‑side scripts, an ASPX webshell can be executed for full remote code execution, with CVSS 3.1 score 6.5 (Microsoft 8.2).

CVE-2026-45454PowerShellRemote Code Execution
0 likes · 14 min read
CVE-2026-45454: SharePoint Server Upload.aspx Path Traversal Leads to Remote Code Execution
Black & White Path
Black & White Path
Aug 9, 2026 · Industry Insights

How Long Can Foreign Security Vendors Survive China’s New Cyber‑Security Review? – The Palo Alto Networks Case

On August 6, 2026, China’s Cyberspace Administration launched a security review of Palo Alto Networks’ products, signaling a rapid end to the golden era of foreign security vendors in China and outlining the regulatory, technical, and market forces reshaping the sector.

China cybersecurity reviewPalo Alto Networksdata localization
0 likes · 7 min read
How Long Can Foreign Security Vendors Survive China’s New Cyber‑Security Review? – The Palo Alto Networks Case
Black & White Path
Black & White Path
Aug 9, 2026 · Information Security

Black Hat Reveal: Single Email Can Hijack Five Major AI Browsers Including Claude, Gemini, and ChatGPT Atlas

At Black Hat USA 2026, Zenity Labs disclosed the "PleaseFix" vulnerability that lets attackers hijack AI browsers via a malicious email without any user interaction, compromising Claude in Chrome, Gemini in Chrome, Perplexity Comet, ChatGPT Atlas, and Copilot Edge, and demonstrated further local‑host exploits and mitigation steps.

AI browsersBlack Hat 2026Intent Collision
0 likes · 8 min read
Black Hat Reveal: Single Email Can Hijack Five Major AI Browsers Including Claude, Gemini, and ChatGPT Atlas